Google launches Assured Open Source Software to help developers defend against supply chain attacks for free, with support for 1,000+ Java and Python packages
Context & Ripple Effects
Assured Open Source Software began in May 2022 as a paid Google Cloud product giving governments and enterprises access to vetted open-source packages, part of a supply-chain security stack Google has been assembling since the 2017 Grafeas metadata API and the 2021 expansion of its Open Source Vulnerabilities database. Today it drops the price to zero for over 1,000 Java and Python packages.
The move lands amid a broader Google push on open-source maintenance: a $1M sponsorship of the Linux Foundation's Secure Open Source pilot and a [[a:1158582|post-summit proposal for an organization serving as a marketplace for open source maintenance]], both following the White House's open-source security summit.
First-order effects
- Any developer can now pull Google-vetted Java and Python packages without paying, removing the cost barrier that previously limited the service to enterprise Google Cloud buyers.
Second-order effects
- Free vetted packages give Google Cloud a new top-of-funnel: teams that adopt its assurance layer face less friction moving onto Google Cloud's broader supply-chain and zero trust tooling, pressuring rivals' equivalent offerings on price.
Third-order effects
- If the free-assurance pattern holds across hyperscalers, package vetting shifts from a billable product to a cloud-differentiation feature, pushing the industry toward the maintenance-marketplace model Google proposed after the White House summit.
The trend: Cloud providers are converting open-source security assurance from a paid enterprise product into a free acquisition funnel for their platforms.